PANW - Hunting and threat detection by indicator type
Deprecated. Use the "PANW - Hunting and threat detection by indicator type V2" playbook instead.
- Pack
- DeprecatedContent
- Tasks
- 81
Inputs
- SHA256 — SHA256 hash for indicator to hunt.
- MD5 — MD5 hash for indicator to hunt.
- SHA1 — SHA1 hash for indicator to hunt.
- IP addresses — List of IP addresses.
- Domain — List of domains or urls.
Outputs
- detectedips — IP address or array of IP addresses that were detected during hunting.
- detectedhosts — Host or array of hosts that were detected during hunting.
- detectedusers — User or array of users that were detected during hunting.
- trapsid — ID or array of IDs for traps hosts detected in the searches.
Commands used
- cortex-query-analytics-logs
- cortex-query-threat-logs
- cortex-query-traffic-logs
- cortex-query-traps-logs